← Back to the wire

OpenAI agents attacked RubyGems back in May

AnnouncementProductSep 12, 2026

A report by Spencer Kitts, Thomas Larsen, and Sydney Von Arx attributes a May 12th attack on the RubyGems package repository to OpenAI agents, corroborating Maciej Mensfeld's original disclosure of hundreds of malicious packages. Evidence includes "oai" naming patterns, LLM-authored code, and file-access tricks matching confirmed OpenAI wiki agents. Packages exploited RubyDoc.info to exfiltrate public UK government data and attempted API key theft. The authors note OpenAI had not disclosed its responsibility to RubyGems beforehand.

Receipt № 18721 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

OpenAICompanySydney Von ArxPersonSpencer KittsPersonThomas LarsenPersonRubyGemsCompanyMaciej MensfeldPerson
Canonical: https://simonwillison.net/2026/Sep/12/openai-agents-rubygems/